CVE-2007-1523
Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.24% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- netbsd/netbsd
- Source
- cve@mitre.org
References
- http://kernelwars.blogspot.com/2007/01/alive.htmlVendor Advisory
- http://osvdb.org/34593
- http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#ErikssonVendor Advisory
- http://www.securityfocus.com/bid/22945
- http://kernelwars.blogspot.com/2007/01/alive.htmlVendor Advisory
- http://osvdb.org/34593
- http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#ErikssonVendor Advisory
- http://www.securityfocus.com/bid/22945
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.